CA Service Management

 View Only
  • 1.  CASMAdmin Credentials for 17.0 Upgrade

    Posted Aug 23, 2017 02:06 PM

      We are doing our first upgrade, going from 14.1 to 17.0 (14.1 was our first version). I am onto Service Catalog and USS update. In the installer, I select use existing database in the Unified Self-Service step and add the "Company Admin Name" and "Company Admin Password" (using CASMAdmin and the password) and I get an error: "Unable to login to the selected Company. Verify the user credentials". I have read everything I could get my hands on but need help understanding a few things. I see the CASMAdmin in Service Desk, Service Catalog, and USS Control Panel but when I "fetch EEM data" from Service Catalog it says it is not in there. When I log into EEM I do not see that account which confirmed it is not in there.

     

      Is the reason I am getting this error because it is trying to directly "log in" to USS from the installer and since there is no account in EEM it can't? I saw an article but since my first version is 14.1 didn't know if it applied here. Can this be corrected by adding the username and existing per this documentation: https://communities.ca.com/thread/241778904-how-to-change-ca-service-management-admin-credentials

     

      If not, is the next likely scenario that the credentials (password) is wrong? If so, can I change it from the Control Panel since it is not in EEM (I see the option in the Control Panel). Sorry for the long post.



  • 2.  Re: CASMAdmin Credentials for 17.0 Upgrade

    Posted Aug 23, 2017 02:32 PM

    Hi Jessie,

     

    You are on the right track. When you installed Service Catalog and USS, EEM was using its internal data store and not pointed to an external LDAP (Active Directory). The CASMAdmin account was created by the install in the EEM internal data store. Later, when you pointed EEM at an external LDAP, connection to the internal data store was lost. You can actually see this by changing EEM back to using its internal data store (try this in your test environment).

     

    Your choices here are:

    1. Switch the EEM back to the internal data store to conduct the upgrade. OR
    2. Create a CASMAdmin account in your Active Directory (with the same password for consistency) and make sure that, in EEM, you put that new account into the same application groups as the internal store CASMAdmin was in.

     

    Cheers,

    Lindsay



  • 3.  Re: CASMAdmin Credentials for 17.0 Upgrade

    Posted Aug 23, 2017 03:24 PM

    Thank you Lindsay, I am trying it now.



  • 4.  Re: CASMAdmin Credentials for 17.0 Upgrade

    Posted Aug 23, 2017 04:04 PM

    I pointed EEM to the Internal Store and verified the credentials work in the applications themselves after pointing to internal but am still getting the error: "Unable to login to the selected Company. Verify the user credentials" when running the installer. Just to confirm, the Company Store Admin and Company Admin Password are for CASMAdmin and the password?  Are there any services that need stopped (I currently have all running)?  The only reference to that I saw was the backup to get the .car file but not sure moving forward after I get it, the instructions make no mention either way.



  • 5.  Re: CASMAdmin Credentials for 17.0 Upgrade

    Posted Aug 23, 2017 04:18 PM

    Hi Jessie,

    I suggest you open a case with CA Support.

    Cheers,

    Lindsay



  • 6.  Re: CASMAdmin Credentials for 17.0 Upgrade

    Broadcom Employee
    Posted Aug 24, 2017 03:32 AM

    Good Morning Jessie.
     
    A:
    As to the 'CASMAdmin' user/userid/account not shown in EEM, please (double) check whether EEM has been configured for ActiveDirectory (AD/LDAP)?
    As stated in the wiki page:
    https://docops.ca.com/ca-service-management/14-1/en/implementing/implementing-ca-service-management-14-1/step-4-install-or-upgrade/install-ca-service-management
    Install CA Service Management
    You can use the CA Service Management Installer to install, upgrade, configure, and integrate the CA Service Management products in the solution.
    The installer performs the prerequisite checks and mandatory validations before installing the products.
    ...
    >> Important!
    If you plan to use CA EEM that is configured with Active Directory,
    - before installing CA Service Management 14.1,
    - ensure to create the CasmAdmin user and OpenSpaceAdminGroup.
    - Associate the CasmAdmin to the OpenSpaceAdminGroup in the Active Directory.
     
    B:
    As to the "Unable to login to the selected Company" error.
    A local test, running the setup.exe program, gets me the same error when I enter incorrect credentials.
    Can you login to EEM with casmadmin/password as such?

     

    Please let me know when this is helpful?
     
    Thanks and kind regards, Louis.



  • 7.  Re: CASMAdmin Credentials for 17.0 Upgrade

    Posted Aug 24, 2017 07:54 AM

    Thank you for the replies. EEM was enabled with AD but I removed it yesterday and enabled the internal store. After that, I ensured that the account is in the OpenSpaceGroup and was able to login to EEM with the credentials with no problem. I am a little confused as why I am getting the error when I am having no problems logging into EEM with the credentials. I prefer to not create an AD account just for the upgrade if it can be avoided.



  • 8.  Re: CASMAdmin Credentials for 17.0 Upgrade
    Best Answer

    Broadcom Employee
    Posted Aug 25, 2017 03:01 PM

    Worked with Jessie on this via a support case we had - 

     

    As this is an inplace upgrade of Service Management 14.1 to 17.1 in QA Environment where:

    - EEM is tied to LDAP
    - Because of Account Security Restrictions, we're not able to create a CASDMAdmin account in AD

    - So we started USS 14.1 first, logged in

    - Via USS Admin (host:port/group/control_panel) portal, we changed default User Role to 'Administrator' and disabled EEM's NTLM Authentication.
    - Via EEM UI, changed EEM to use internal data store and verified that CASMAdmin account does indeed exist in EEM
    - Verified that CASMAdmin account can now login to USS 14.1 pre-upgrade
    - Launched 17.0 installer and completed necessary screens
    - As this is an in-place upgrade,  the 'Use Existing Database' option is not required on the USS Database Detail page of the installer
    - Upgrade started successfully

     

    The 17.0 (and 14.1) installer is hard coded at this time to use  casmdadmin account to install/integrate with USS, and that user has to be in a group called OpenSpaceAdminGroup.  Unfortunately because of this and that we could not get that account created in AD for this installation, we had to move EEM back to local store to complete the upgrade operation successfully.

     

    _R